Assisted third-party password authentication
Abstract
Disclosed herein are system, method, and apparatus for assisted third-party password authentication. The method performed at a client device includes creating a secure connection from an inline frame associated with a first application on the client device to an authorization server for accessing a second application. The method includes identifying, by the inline frame, one or more events that represent inputs for a user authorization credential, and proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection. The method includes receiving an authorization code from the authorization server in response to the proxying. The method includes redirecting, by the inline frame, the authorization code to the application on the client device. The method includes transmitting, from the client device to the authorization server, the authorization code to receive an access token for accessing the second application.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method, comprising:
creating a secure connection from an inline frame associated with a first application on a client device to an authorization server for accessing a second application;
identifying, by the inline frame, one or more events that represent inputs for a user authorization credential;
proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection;
redirecting, by the inline frame, an authorization code to the first application on the client device;
transmitting, to the authorization server, the authorization code to receive an access token for accessing a second application;
generating, by the inline frame, a form for receiving the user authorization credential; and
updating the form with a graphical symbol to avoid interrogation of a document object model (DOM) element associated with the form;
inserting the inline frame in the first application according to a restricted access policy; and
closing the inline frame upon receiving the access token from the authorization server.
2. The method of claim 1 , further comprising:
inserting the inline frame in the first application based on an agreement between the first application and the second application according to the restricted access policy.
3. The method of claim 1 , further comprising:
encrypting the one or more events proxied to the authorization server using a public-private key pair.
4. The method of claim 1 , wherein creating the secure connection comprises:
establishing a connection between the inline frame and the authorization server using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS).
5. The method of claim 1 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page.
6. The method of claim 1 , wherein the access token is valid for a predetermined time interval.
7. The method of claim 1 , further comprising providing an address of the second application at the first application.
8. A system, comprising:
a memory; and
a processor coupled to the memory, the processor configured to:
transmit a request to an inline frame associated with a first application to render a form configured to receive authorization credential information for accessing a second application;
verify the authorization credential information upon receiving the authorization credential information in response to the inline frame receiving or listening for a key event;
transmit an authorization code to the inline frame in response to authorizing the authorization credential information; and
transmit an access token to the first application via the inline frame, wherein the first application uses the access code to access the second application.
9. The system of claim 8 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page.
10. The system of claim 8 , wherein the inline frame is generated in the first application based on an agreement between the first application and the second application according to a restricted access policy.
11. The system of claim 8 , wherein a connection between a server and inline frame is formed using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS).
12. The system of claim 8 , wherein the access token is valid for a predetermined time interval.
13. The system of claim 8 , wherein the inline frame includes an HTML tag, IP address, or a fully qualified domain name (FQDN) of a server.
14. The system of claim 8 , wherein the key event is encrypted using a public-private key-pair.
15. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:
creating a secure connection from an inline frame associated with a first application on a client device to an authorization server for accessing a second application;
identifying, by the inline frame, one or more events that represent inputs for a user authorization credential;
proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection;
redirecting, by the inline frame, an authorization code to the first application on the client device;
transmitting, to the authorization server, the authorization code to receive an access token for accessing the second application;
generating, by the inline frame, a form for receiving the user authorization credential; and
updating the form with a graphical symbol to avoid interrogation of a document object model (DOM) element associated with the form;
inserting the inline frame in the first application according to a restricted access policy; and
closing the inline frame upon receiving the access token from the authorization server.
16. The non-transitory computer-readable medium of claim 14 , wherein the operations further comprise:
inserting the inline frame in the first application based on an agreement between the first application and the second application according to the restricted access policy.
17. The non-transitory computer-readable medium of claim 14 , wherein the operations further comprise:
encrypting the one or more events proxied to the authorization server using a public-private key pair.
18. The non-transitory computer-readable medium of claim 14 , wherein creating the secure connection comprises:
establishing a connection between the inline frame and the authorization server using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS).
19. The non-transitory computer-readable medium of claim 14 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page.
20. The non-transitory computer-readable medium of claim 14 , wherein the access token is valid for a predetermined time interval.Join the waitlist — get patent alerts
Track US11750608B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.